skills/simota/agent-skills/vigil/Gen Agent Trust Hub

vigil

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements Detection-as-Code (DaC) workflows using industry-standard security practices. For example, the CI/CD templates in reference/detection-as-code.md explicitly instruct the use of full commit SHAs for GitHub Actions (e.g., actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11) to prevent supply-chain attacks via mutable tags.
  • [SAFE]: The skill promotes the use of OIDC (OpenID Connect) for cloud authentication in deployment pipelines, ensuring short-lived credentials and avoiding the storage of long-lived static secrets.
  • [SAFE]: External references and dependencies are directed toward trusted and well-known organizations, such as MITRE ATT&CK, SigmaHQ, and the official Python Package Index (PyPI). These resources are documented neutrally and align with the skill's stated purpose.
  • [SAFE]: The threat intelligence management section in reference/ioc-threat-intel.md correctly handles the Traffic Light Protocol (TLP) and enforces indicator expiration (valid_until) to prevent stale data from causing alert fatigue, demonstrating professional operational security.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:48 PM
Security Audit — agent-trust-hub — vigil